Artificial intelligence (“AI”) tools are increasingly being deployed across the employee benefits landscape: from claims administration and customer service to investment analysis and participant engagement. While these technologies promise efficiency and cost savings, recent litigation and regulatory activity underscore that the use of AI in benefits administration carries meaningful legal and fiduciary risk. Below we highlight key developments that plan sponsors can watch as they assess their use of AI in connection with employee benefit plans.
1. AI Tools Used by Plan Sponsors and Third-Party Service Providers
AI tools are increasingly embedded in both internal and third-party platforms used by plan sponsors and participants. Health insurers, benefits providers, and plan sponsors are rolling out AI-driven tools on their websites (e.g., plan benefits sites) to help participants and beneficiaries locate providers, estimate costs, and better understand their coverage.
Recent litigation outside of the AI context has highlighted this risk:
- In Watson v. Dell Technologies, Inc., et al (D. Colo. 2019), the U.S. District Court for the District of Colorado held that an employer breached its ERISA fiduciary duties by failing to fully inform an employee about the need to convert his life insurance policy to maintain coverage. In this case, the employee’s voluntary separation agreement indicated that health plan benefits would continue following termination, subject to payment of premiums, and life insurance benefits would terminate, subject to the right to convert. When the employee asked how to pay for the benefits that would continue, the employer provided information only on the health plan benefits that would continue. The employee did not convert his life insurance, and after his widow’s life insurance claim was properly denied under the plan, the widow sued the employer for breach of fiduciary duty. The Court awarded the employee’s widow the full amount of the life insurance benefit reduced by the amount of premiums that would have been required to maintain the coverage, holding that employers must provide complete and accurate information in response to benefit inquiries. In other words, fiduciaries have an obligation in certain cases to broadly interpret employee questions and to answer questions the employee has not asked.
Comparable principles may apply in the AI context, particularly to the extent that AI tools provide incomplete or incorrect information, which participants then use to make decisions about their benefits.
| In the retirement plan space, investment management consultants and advisors are increasingly leveraging AI to analyze investment costs and performance, construct model portfolios, and generate investment recommendations. These tools may rely on large datasets and predictive analytics that are not always transparent to plan fiduciaries evaluating the advice. AI is also being used for recordkeeping and to draft communications to participants about their plans. | In the welfare plan space, insurers and plan sponsors are increasingly using AI tools to answer participant questions about benefit eligibility and coverage based on the AI tool’s “read” of plan documents and information posted to the insurer’s or sponsor’s website. If a participant relies to their detriment on AI-generated answers that do not accurately and completely reflect the participant’s eligibility or coverage – whether due to incorrect information contained in the documents, AI error, or AI’s inability to understand what information is important to the participant (see discussion of the Watson case above) – that reliance could subject the insurer or plan sponsor to fiduciary breach claims. |
2. Recent Litigation Alleging AI Failures in Claims Determinations
Litigation challenging the use of AI in claims administration has already emerged. Recent lawsuits allege that insurers and claims administrators have breached their fiduciary duties by improperly relying on AI-driven tools when making health claim determinations. For example, in Kisting-Leung v. Cigna (E.D. Cal. 2023), plaintiffs alleged that Cigna used automated systems to deny claims without meaningful individualized review, purportedly resulting in systemic ERISA violations.
Allegations raised by plaintiffs in other cases include inappropriate reliance on algorithmic models to prematurely terminate coverage for post-acute care despite contrary clinical evidence, and that AI tools prioritize cost containment over patient-specific medical necessity. To date, no lawsuit has reached a substantive conclusion as to whether a defendant’s actions violate ERISA. And so far, the AI-affiliated fiduciary breach claims have been asserted against third party administrator fiduciaries rather than the employer. However, the lawsuits more generally reflect scrutiny over whether AI tools are being used in a manner consistent with ERISA’s fiduciary and procedural requirements. Because ERISA plan fiduciaries have a duty to monitor their service providers, plan participants could use these cases as a roadmap for claims against the plan fiduciaries.
3. Regulatory Efforts Addressing AI Use
Globally, some regulators are moving to establish guardrails around AI. For example, the European Union’s AI Act takes a risk-based approach, subjecting “high-risk” AI systems – potentially including those used in healthcare and benefits administration – to stringent governance, documentation, and human-oversight requirements.
In the United States, explicit federal regulatory guidance remains outstanding. In 2025 the Trump administration published America’s AI Action Plan and two Executive Orders titled Removing Barriers to American Leadership in Artificial Intelligence and Ensuring A National Policy Framework for Artificial Intelligence, as well as an Executive Order published in 2026 titled Promoting Advanced Artificial Intelligence Innovation and Security – each illustrating the administration’s policy emphasis on innovation in contrast to the EU’s risk-based approach. A provision that would have provided for a ten-year moratorium on state and local regulation of AI was proposed in, but ultimately removed from, H.R.1 (the House version of what became the 2025 budget reconciliation act) – indicating that while the federal government does not appear to be currently focused on regulation, there appears to be some Congressional interest in striking a balance between AI innovation and regulation.
As evidence of this balance, while the administration is focused on innovation, several states have enacted or proposed laws seeking to regulate the use of AI in areas identified as “high-risk”, such as healthcare, insurance coverage and pricing, and financial services, as decisions in these areas can have significant impact on individuals. For example:
- SB 1120, California’s Physicians Make Decisions Act, went into effect on January 1, 2025. The act amends healthcare and insurance laws to regulate how health plans and disability insurers may use AI, requiring physician oversight and prohibiting AI alone from denying, delaying, or modifying medical necessity decisions.
- SB 26-189, Colorado’s framework for automated decision-making technology, currently set to go into effect in January 2027, imposes duties on developers and deployers of AI systems that “materially influence a consequential decision” in areas such as healthcare, housing, and finance.
- Some states, as seen in SB 149, Utah’s AI Policy Act, have addressed disclosure concerns, requiring an online interface to prominently indicate when a consumer is interacting with AI as opposed to a person when used in regulated professions, such as in medical, legal, or financial contexts.
These laws may indirectly affect plan sponsors through the requirements being imposed on their vendors and service providers.
4. Thompson Hine Takeaways for Plan Fiduciaries
As AI becomes more prevalent in the benefits administration space, plan fiduciaries will want to pay close attention to and ask questions about the AI tools being used in connection with their benefit plans. ERISA requires plan fiduciaries to prudently evaluate and monitor plan service providers and to provide clear and accurate information to participants in response to their questions about plan benefits – all of which can be impacted by AI.
To demonstrate fiduciary prudence and put themselves in strong positions to defend against potential fiduciary breach claims, plan fiduciaries may wish to consider the following recommended practices, to the extent applicable, in connection with their review and use of AI in the benefits space:
- Confirm whether and to what extent their plan’s claims administrator uses AI, automated systems, predictive algorithms, or other similar tools to determine participant claims and appeals. Understand what level of human oversight or review is applied to any such decisions and what processes exist for participants to challenge any AI-based decisions.
- Confirm whether third-party vendor AI usage complies with their company’s AI governance policies, if any.
- If a plan’s third-party vendor uses an AI tool on its website or platform, ask written questions of the vendor to confirm they understand the tool’s functionality and expected use. Plan fiduciaries may also consider requesting demonstrations of the tool by the vendor and testing the tool (including by a plan sponsor employee who reports to the plan fiduciary) to assess the quality of information generated. Understanding how AI tools are trained and what they do (and their limitations) is an important first step in managing risk.
- Explicitly address AI use in vendor and service provider agreements, including through representations that the vendor’s use of AI complies with applicable federal and state laws, audit rights, data usage rights, and indemnification provisions tied to AI-driven errors, claims determinations, regulatory violations, or litigation. Contractual allocation of AI risk is likely to become increasingly important as these tools become more commonplace. Including contractual language regarding AI use forces plan fiduciaries and vendors to address how AI will be used in connection with the plan and will provide greater transparency into the vendor’s AI usage and/or AI tool features.
- Consider whether applicable fiduciary coverage, errors and omissions coverage, and cybersecurity insurance policies address AI usage and/or provide for any gaps in coverage related to AI usage.
- Consider whether potential beneficial uses of AI are currently being overlooked – for example, to improve quality of care or to better manage plan costs. If a prudent person under similar circumstances would utilize available AI to the benefit of their plan participants, plan fiduciaries may want to consider adopting a similar approach.
- If the plan sponsor has a presence in the EU, the plan sponsor may wish to have its legal counsel evaluate the EU AI Act’s potential application to the plan.
